Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-3450

34
FAUCET Score

CVE-2021-3450 is a high-severity vulnerability in OpenSSL versions 1.1.1h through 1.1.1j, affecting various products including fedoraproject, freebsd, and oracle. It stems from an error in the X509_V_FLAG_X509_STRICT flag implementation, which could allow non-CA certificates to issue other certificates, bypassing a critical security check if an application explicitly sets this flag and either removes or overrides the default certificate purpose. The vulnerability has a CVSS score of 7.4 (High), indicating a network-based attack with high impact on confidentiality and integrity, but requiring high attack complexity. While the EPSS score is low, suggesting limited real-world exploitation, the FAUCET Risk Score of 47/100 highlights its potential. There is no evidence of active exploitation, nor are there publicly available Metasploit, Nuclei, or ExploitDB modules. However, the vulnerability has garnered significant community attention with 7 mentions in discussions and 3 media articles, indicating awareness among security professionals.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.1.1h, < 1.1.1kCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
12.2CPE matchmatch criteria
cpe:2.3:o:freebsd:freebsd:12.2:-:*:*:*:*:*:*
12.2CPE matchmatch criteria
cpe:2.3:o:freebsd:freebsd:12.2:p1:*:*:*:*:*:*
12.2CPE matchmatch criteria
cpe:2.3:o:freebsd:freebsd:12.2:p2:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:netapp:santricity_smi-s_provider_firmware:-:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.4HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.2
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
18.34%
Probability of exploitation in next 30 days
EPSS Percentile
96.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.1834 is in the 84th percentile among its peer group of 8,915 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (25)

microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8)Fixed in: 15.9.40
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10)Fixed in: 16.11.5
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2019 version 16.9 (includes 16.0 - 16.8)Fixed in: 16.9.12
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2019 version 16.7 (includes 16.0 – 16.6)Fixed in: 16.7.20
View patch
microsoftpatch availablevia msrc
Product: Microsoft Visual Studio 2019 version 16.4 (includes 16.0 - 16.3)Fixed in: 16.4.27
View patch
oraclepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_jk-0:1.2.48-13.redhat_1.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_md-1:2.0.8-33.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_security-0:2.9.2-60.GA.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-nghttp2-0:1.39.2-37.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-openssl-1:1.1.1g-6.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-openssl-chil-0:1.0.0-5.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-openssl-pkcs11-0:0.4.10-20.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: openssl-1:1.1.1g-15.el8_3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 3.1Fixed in: openssl
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 3 for RHEL 7Fixed in: tomcat-native-0:1.2.23-24.redhat_24.ep7.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.4 on RHEL 7Fixed in: jws5-tomcat-native-0:1.2.25-4.redhat_4.el7jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.4 on RHEL 8Fixed in: jws5-tomcat-native-0:1.2.25-4.redhat_4.el8jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization 4 for Red Hat Enterprise Linux 8Fixed in: redhat-virtualization-host-0:4.4.5-20210330.0.el8_3
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_http2-0:1.15.7-14.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_cluster-native-0:1.3.14-20.Final_redhat_2.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-httpd-0:2.4.37-70.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBCS 2.4.37 SP7Fixed in: openssl
View patch
rustpatch availablevia ghsa
Product: openssl-srcFixed in: 111.15.0

Vendor Advisories (3)

microsoft2021-Oct/CVE-2021-3450Important

OpenSSL: CVE-2021-3450 CA certificate check bypass with X509_V_FLAG_X509_STRICT

Oct 12, 2021
rustGHSA-8hfj-xrj2-pm22high

Certificate check bypass in openssl-src

Aug 25, 2021
redhatCVE-2021-3450Important

openssl: CA certificate check bypass with X509_V_FLAG_X509_STRICT

Mar 25, 2021

References

cert-portal.siemens.com / productcert/pdf/ssa-389290.pdf
Third Party Advisory
git.openssl.org / gitweb
kb.pulsesecure.net / articles/Pulse_Security_Advisories/SA44845
Third Party Advisory
kc.mcafee.com / corporate/index
Third Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/CCBFLLVQVILIVGZMBJL3IXZGKWQISYNP
mta.openssl.org / pipermail/openssl-announce/2021-March/000198.html
Mailing ListVendor Advisory
psirt.global.sonicwall.com / vuln-detail/SNWLID-2021-0013
Third Party Advisory
security.freebsd.org / advisories/FreeBSD-SA-21:07.openssl.asc
Third Party Advisory
security.gentoo.org / glsa/202103-03
Third Party Advisory
security.netapp.com / advisory/ntap-20210326-0006
Third Party Advisory
tools.cisco.com / security/center/content/CiscoSecurityAdvisory/cisco-sa-openssl-2021-GHY28dJd
Third Party Advisory
openssl.org / news/secadv/20210325.txt
Vendor Advisory
oracle.com / security-alerts/cpuApr2021.html
PatchThird Party Advisory
oracle.com / security-alerts/cpuapr2022.html
PatchThird Party Advisory
oracle.com / /security-alerts/cpujul2021.html
PatchThird Party Advisory
oracle.com / security-alerts/cpujul2022.html
PatchThird Party Advisory
oracle.com / security-alerts/cpuoct2021.html
PatchThird Party Advisory
tenable.com / security/tns-2021-05
Third Party Advisory
tenable.com / security/tns-2021-08
Third Party Advisory
tenable.com / security/tns-2021-09
Third Party Advisory
openwall.com / lists/oss-security/2021/03/27/1
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2021/03/27/2
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2021/03/28/3
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2021/03/28/4
Mailing ListThird Party Advisory